VYPR

npm · Malicious package advisory

Malware

tiny-focusgroup-helper

GHSA-vj2w-9332-v252

Malicious code in tiny-focusgroup-helper (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (9c6d210f6c61d0ec49fac4bf487a2d71966b1f3dd59653d8a8fdf12e04f9b306)
[email protected] declares itself as a focus-group accessibility helper, but thunderboltRegistry.js runs an IIFE at require time that executes `whoami`, `uname -a`, `ifconfig`/`ip addr`, and reads `/etc/hosts` via child_process, and POSTs/GETs the output as query parameters to the hardcoded plaintext endpoint http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3, along with a beacon containing node version, platform, and pid. The dxpoc.gt.tc host is a dynamic-DNS domain unrelated to any legitimate publisher. The package's exported surface (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry) mirrors internal Wix thunderbolt registry module names and the shipped manifest references static.parastorage.com, consistent with a dependency-confusion/module-impersonation lure targeting Wix build environments.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/tiny-focusgroup-helper/MAL-2026-17527.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/tiny-focusgroup-helper/MAL-2026-17527.json
- https://www.npmjs.com/package/tiny-focusgroup-helper/v/1.0.0
- https://github.com/advisories/GHSA-vj2w-9332-v252

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.